Monitor correlation rules
Monitor correlation rule executions, issues, and processing status.
Cortex Cloud audits all correlation rule executions in the correlations_auditing dataset. The dataset records the query initiation times, end times, retry attempts, failure reasons, and other useful metrics. You can use this dataset to monitor your correlation executions. Cortex Cloud also provides OOTB health issues that are generated when a correlation rule completes with errors.
In the correlations_auditing dataset, audit entries are added as follows:
The rule starts executing. This is audited with the status of Initiated or Initiated Manually.
The rule completes successfully. This is audited as Completed.
The rule completes with errors. This is audited as Error.
Last updated
Was this helpful?
